However that would've likely done little to impede this attack if it is backed by organized crime or by a state as is being speculated. It is trivially easy for those types of actors to simply use a stolen identity or create an entirely plausible one out of thin air.
Can you provide a historical example of when something like that has happened?
It sounds like hyperbole to say that it is 'easy' (even for a state) to impersonate a real-life identity or create one for a professional developer with a multi-year work history.
For security-hardened distributions, I can easily imagine a security control where contributor identity must be public and publicly verifiable, and to reject code which cannot be reliably attributed. Don't like it? Contribute to software with less impact instead.
I don't think this is really a structural problem requiring these kind of sweeping changes; it's just an occasional rare incident.
We only know about the ones found.
It's more or less impossible to prove the absence of these type of bugs, so you can always say "we only know about the ones found" because that will always be true.
Either way, you're going to have to do better than "this could perhaps possibly maybe be a more common problem" if you want such a huge sweeping change as maintainers of open source projects to "be identifiable". What does that even mean in practical terms? They upload their passports? To who? Who and how do they verify this? How do we prevent edited passports? What about privacy? etc. etc. etc.
All for something we don't even know is a problem.
How about some responsibility for the IBM devs who could have contributed to the library they decided to paste into sshd?